# How to attain Okta Device Attestation for Android devices? Last updated: July 24, 2026 This guide explains how to enable Okta Device Attestation for Android devices managed through Mobile Device Manager Plus, required for Okta SSO extension provisioning and Okta Device Trust. Administrators add an Android device platform in Okta to obtain a secret hint and org URL, add the Okta Verify app to the MDM App Repository, then enter the Org URL and secret key into the app's Management Hint configuration and distribute it to devices. Users then set up Okta Verify with their credentials and sign in to an org-allotted app to complete attestation. Managed devices should be attested by Okta for **provisioning SSO extension with Okta** and **Okta Device Trust**. Attestation can be achieved for Android devices by configuring a managed app with a management hint (shared secret) that is sent to the device through Mobile Device Manager Plus. ## Overview A **secret hint** should be included in Android devices for integrating Okta with MDM console. To do that, the administrator or technician must add a management platform for Android in Okta and get the secret hint. Then this secret hint should be added to the [MDM App Configuration](https://www.manageengine.com/mobile-device-management/managed-app-configuration.html), and the app should be distributed to the device. Follow the detailed steps specified below to integrate Okta with MDMP for Android devices. ![How to attain Okta Device Attestation for Android devices? illustration 3](https://cdn.manageengine.com/mobile-device-management/images/Okta-DA-Flowchart-1.png) ### Step 1: Adding Device Management Platform in Okta You have to start by adding the **device platform** in the **Okta** portal. ![How to attain Okta Device Attestation for Android devices? illustration 4](https://cdn.manageengine.com/mobile-device-management/images/Okta-DA-Android_1.png) 1. Login to the **Okta portal**, and under **Security**, go to **Device Integrations** and click on **Add Platform**. ![How to attain Okta Device Attestation for Android devices? illustration 5](https://cdn.manageengine.com/mobile-device-management/images/Okta-DA-Android_2.png) 2. Then choose the platform as **Android** and go to the subsequent window by clicking **Next**. ### Step 2: Copying the Secret Hint from Okta ![How to attain Okta Device Attestation for Android devices? illustration 6](https://cdn.manageengine.com/mobile-device-management/images/Okta-DA-Android_3.png) **Copy** the **Secret key** and the **organisation URL** (from the top right corner of the Okta dashboard). Then specify **ManageEngine** as the name of your device management provider. For the enrollment link, add the [self enrollment link](https://www.manageengine.com/mobile-device-management/help/enrollment/mdm_byod.html) from the MDM console and click **Save**. You can access the self enrollment link by navigating to the Enrollment tab under **Enrollment > Self Enrollment**. ### Step 3: Adding the configuration to Okta Verify app The next step is to add the configurations to the **Okta Verify app**. The Okta Verify App can be added to the MDM App Repository either using [Android for Work (Managed Google Play)](https://www.manageengine.com/mobile-device-management/help/app_management/android_app_management.html) or by adding the app from the [Play Store](https://www.manageengine.com/in/mobile-device-management/help/app_management/mdm_creating_app_repository.html#android_store_apps). Once the app is added to the **App Repository**, follow the steps below: 1. In the MDM console, navigate to **Device Management** and choose **App Repository**. Then select the **Okta Verify App**. ![How to attain Okta Device Attestation for Android devices? illustration 7](https://cdn.manageengine.com/mobile-device-management/images/Okta-DA-Android_4.png) 2. Choose **Configurations**, then enter the **Org URL** and paste **Secret key** for the **Management Hint**. After that, click **Save** and distribute the app to the devices. 3. For successful device attestation, the user should setup Okta Verify using their credentials and then login to any of the org allotted apps. ## Frequently asked questions ### Why do I need to configure Okta Device Attestation for Android devices? It's required for provisioning the SSO extension with Okta and for Okta Device Trust — Okta needs a management hint (shared secret) sent to the device through Mobile Device Manager Plus to confirm the device is managed. ### How do I get the secret hint from Okta? In the Okta portal, go to Security > Device Integrations > Add Platform, choose Android, then copy the Secret key and organization URL from the top-right corner of the Okta dashboard. ### Where do I add the Okta Verify app configuration in Mobile Device Manager Plus? Add the Okta Verify app to the App Repository (via Managed Google Play or the Play Store), then under Configurations enter the Org URL and paste the Secret key into the Management Hint field before distributing the app. ### How do I know a device has been successfully attested? The user needs to set up Okta Verify with their credentials and sign in to at least one org-allotted app — once that's done, the device attains attested status.